Å©·¡Å· ÇÇÇØ

 423, 11/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   midori68
   http://spacelab.khu.ac.kr/~ken
   ÇØÅ·´çÇÑ °Í °°½À´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=46 [º¹»ç]


¾îÁ¦±îÁö¸¸ Çصµ ¾ø´ø Á¤Ã¼ºÒ¸íÀÇ µð·ºÅ丮°¡ Á¦ °èÁ¤ ¾È¿¡ »ý°å½À´Ï´Ù..
µð·ºÅ丮 ¾È¿¡´Â ¿©·¯°³ÀÇ µð·ºÅ丮¿Í ÆÄÀϵéÀÌ µé¾î ÀÖ¾ú´Âµ¥, Á¦°¢°¢ ¼ÒÀ¯±Çµµ ´Ù¸£°í.. µµ¹«Áö ¹«½¼ ¸ñÀûÀ¸·Î ¸¸µç°ÇÁö ¾Ë ¼ö °¡ ¾ø´Â °ÍµéÀÌ´õ±º¿ä
°Ô´Ù°¡ Áö¿öÁöÁöµµ ¾Ê½À´Ï´Ù..

rm ¸í·Â¾î°¡ ¾È ¸Ô¾î¿ä

±×·¡¼­ ÀÏ´ÜÀº ¼­¹ö¿¡¼­ x-window·Î µé¾î°¡¼­ Áö¿ü´Âµ¥, Áö¿ï¶§ º¸´Ï ¸î °¡Áö ¼ö»óÇÑ À̸§ÀÇ ½ÇÇàÆÄÀÏ°ú tar ÆÄÀÏÀÌ ÀÖ´õ±º¿ä

¿ì¼± linuxkit.tar ¶ó´Â °ÍÀÌ ¹¹ÇÏ´Â °ÇÁö ±Ã±ÝÇÕ´Ï´Ù
±×³É Áö¿ö¹ö·È´Âµ¥.. ¾Æ¹«·¡µµ ÀÌ°Ô ÇØÅ·¿¡ »ç¿ëµÈ °Í °°¾Æ¿ä. ¹°·Ð Á¦ °ÍÀº ¾Æ´Õ´Ï´Ù.
¶ÇÇϳª, p.tar ¶ó´Â ¾ÆÄ«À̺êÆÄÀÏÀÌ À־ ÀÌ°Ç È¤½Ã³ª Çؼ­ ´Ù¿î·Îµå ¹Þ¾ÆºÃ´Âµ¥¿ä.
p.c¶ó´Â ¼Ò½ºÆÄÀÏ°ú p¶ó´Â ½ÇÇàÆÄÀÏÀÌ µé¾îÀÖ´õ±º¿ä

p.c¿¡ ÀûÈù ³»¿ëÀº¿ä



/*
* Linux kernel ptrace/kmod local root exploit
*
* This code exploits a race condition in kernel/kmod.c, which creates
* kernel thread in insecure manner. This bug allows to ptrace cloned
* process, allowing to take control over privileged modprobe binary.
*
* Should work under all current 2.2.x and 2.4.x kernels.
*
* I discovered this stupid bug independently on January 25, 2003, that
* is (almost) two month before it was fixed and published by Red Hat
* and others.
*
* Wojciech Purczynski <cliph@isec.pl>
*
* THIS PROGRAM IS FOR EDUCATIONAL PURPOSES *ONLY*
* IT IS PROVIDED "AS IS" AND WITHOUT ANY WARRANTY
*
* (c) 2003 Copyright by iSEC Security Research
*/

#include <grp.h>
#include <stdio.h>
#include <fcntl.h>
#include <errno.h>
#include <paths.h>
#include <string.h>
#include <stdlib.h>
#include <signal.h>
#include <unistd.h>
#include <sys/wait.h>
#include <sys/stat.h>
#include <sys/param.h>
#include <sys/types.h>
#include <sys/ptrace.h>
#include <sys/socket.h>
#include <linux/user.h>

int main(int argc, char ** argv)
{
        prepare();
        signal(SIGALRM, sigalrm);
        alarm(10);
        
        parent = getpid();
        child = fork();
        victim = child + 1;
        
        if (child == -1)
                fatal("[-] Unable to fork");

        if (child == 0)
                do_child();
        else
                do_parent(argv[0]);

        return 0;
}





ÀÌ·± °ÍÀÔ´Ï´Ù.
ÀÌ°Ô ¹¹ÇÏ´Â ¼Ò½ºÀÎÁö Á» ¾Ë·ÁÁÖ¼¼¿ä~~
±×¸®°í ¾Æ¸¶µµ ¹éµµ¾î°¡ ¸¸µé¾îÁ® ÀÖÀ» °Í °°Àºµ¥, ã¾Æ¼­ Áö¿ì´Â ¹æ¹ýµµ Á» ºÎŹµå¸³´Ï´Ù..
¶ÇÇϳª.
rm ¸í·É¾î°¡ ÇØÅ·´çÇÑ µÚ·Î °è¼Ó ¾È µË´Ï´Ù.
$rm *.* ¶ó°í Çϸé
Segmentation fault ¶ó°í ³ª¿À´Âµ¥¿ä...
¾î¶»°Ô ÇØ¾ß ÇÏÁÒ?

  Hit : 4530     Date : 2004/02/13 04:26



    
ÂÁ ÁÖ¼®¿¡ ÀûÈù¹Ù¿Í °°ÀÌ exploitÄÚµå ÀΰͰ°½À´Ï´Ù..;; ÀÏÀÏÈ÷ ã¾ÆÁö¿ì´Â ¹æ¹ý¹Û¿£ ¾øÀ»µí... 2004/02/13
ChuRack ÇØÅ· ´çÇϼ̱º¿ä...p.cÆÄÀÏÀº ¸®´ª½º Ptrace¸¦ ÀÌ¿ëÇÑ ÀͽºÇ÷ÎÀÕÀ¸·Î.. 2004/02/14  
ChuRack root°èÁ¤À» ȹµæÇÒ ¼ö ÀÖ½À´Ï´Ù.¶ÇÇÑ ¹éµµ¾î¶ó´øÁö..rm¿¡ °üÇÑ°ÍÀ» ÀÚ¼¼È÷ »ìÆì º¸Áö ¾Ê´Â ÀÌ»ó ¸ð¸£°Ú±º¿ä... 2004/02/14  
a ÁÖ¼®º¸´Ï±î ÀÌ ÄÚµå´Â ·¹À̽º ÄÁµð¼Ç ÀͽºÇ÷ÎÀÕ ¾î¼±¸ Àú¼±¸ ±×·¯³×¿ä 2004/05/08
a rmÀ» ¼öÁ¤Çؼ­ ¹öÆÛ °ªÀ» ÀÛ°Ô ÇÑ °Í °°±º¿ä.. 2004/05/11
a ¿ì¼±, Á¦ ÃßÃøÀ¸·Î´Â ´Ô°ú ¿ø¼ö¸¦ Áø »ç¶÷ Áß¿¡ ÄÄÇ»Å͸¦ ÀßÇÏ´Â »ç¶÷ÀÌ ¸¶À½¸Ô°í ÇÏ´Â Áþ °°½À´Ï´Ù. ¸®´ª½º¸¦ ¹Ð°í ´Ù½Ã ±ò¾Æº¸¼¼¿ä. È®½ÇÇÏ°Ô ´çÇϼ̳׿ä... 2004/05/11
a ±×¸®°í, ¹Ð±âÀü¿¡ ¸®´ª½ºÀÇ ·Î±×¸¦ È®ÀÎÇؼ­ ÀÌ·± ÁþÀ» ÇÑ »ç¶÷ÀÇ IPÀ» ½ºÅ©·¦Çϼż­ »çÀ̹ö °æÂû¿¡ ³Ñ°Ü¹ö¸®½Ê½Ã¿À. 2004/05/11
  ÇØÅ·´çÇÑ °Í °°½À´Ï´Ù[7]     midori68
02/13 4529
222   ·Î±×ÀÎÀÌ ¾ÈµÈ´Ù¸é.....     miae40
08/03 3415
221   ÇØÄ¿°¡ µÇ°í½ÍÀºµ¥[1]     mepcross
10/28 3951
220   ¡ÚÀú±â ÄÄÇ»ÅÍ ÀßÇÏ½Ã´ÂºÐµé ´äº¯Á» ºÎŹµå·Á¿ä; Àç°¡ Ãʺ¸¶ó¼­¡Ú;[6]     MazLat
08/13 3571
219   ¡Ú ÇÁ·Î±×·¥¾Ö ´ëÇؼ­ Àß ¸ð¸£´Â´ë.. ´äº¯Á»^^* ¡Ú[3]     MazLat
08/20 3458
218   ·¹Áö½ºÆ®¸®¸¦ º¸¸é ÀÚ²Ù keyhookÀÌ ³ª¿Í¿ä[3]     MaySecond
09/11 3708
217   ¾È³çÇϼ¼¿ä.^.^ ½Å¹®±â»ç Àдٰ¡ ±Ã±ÝÇؼ­...ipÃßÀû°ü·ÃÀÔ´Ï´Ù.     manho78
05/16 4037
216   ±ÞÇÔ...¸®Çôëȯ¿µ[2]     makayomi
02/13 3398
215   ¾È³çÇϼ¼¿äÁû·éµå¸³´Ï´Ù[2]     magiczero4
03/16 3240
214     [re] Á¦ ´ÙÀ½¸á ºñ¹øÀÌ ÇØÅ·´çÇÑ°Í °°Àºµ¥..ºñ¹øµµ ÇØÅ· ÇÒ ¼ö ÀÖ³ª¿©?     lucifertear
02/14 4444
213   ÀÌ·±°Å Áú¹®Çصµ µÅ³ª¿©?[4]     loves79
07/10 3483
212   À©µµ¿ì º¹±¸ CD¿¡ °üÇÑ Áú¹®[1]     lodtkr024
08/26 3856
211   ¾ÆÀ̵ð¶û ºñ¹øÀ» Å©·¡Å·(?) ´çÇß¾î¿ä![7]     lmw22c
09/09 5008
210     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..     lkj22
08/16 2914
209     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..[3]     lkj22
08/16 3236
208   ¿ÍÀÌÆÄÀÌ ÇØÅ·[1]     LK7C SINEAD
09/17 3898
207     [re] ¡Ú½ºÅäÄ¿ÇØÅ·¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù °í¼ö´Ôµé ´äº¯ºÎŹµå¸³´Ï´Ù     ljh0234
09/03 3648
206   ±×·³ ÀÌ·±°æ¿ìµµ ÇØÅ·ÀÌ µÇ´ÂÁö¿ä[3]     libu1129
12/19 4212
205   ÇØÅ·À» ¾î¶² °æ·Î·Î ÇÏ°Ô µÇ´Â °ÇÁö=¤µ=;[2]     libu1129
12/18 4346
204   Å©·Î½º »çÀÌÆ®¿¡´ëÇÑ º¸¾ÈÀ» ¾î¶±ÇØ ÇØ¾ß ÇÒ±î¿ä?     lhj83
11/08 3312
[1].. 11 [12][13][14][15][16][17][18][19][20]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org